Skip to main content

Financial crime4 min read

How mule networks cash out before the overnight review runs

Mule networks exist to move stolen money faster than an institution can review it. Following the funds from the first credit to the final withdrawal shows where detection has to sit, and why a nightly batch tends to arrive after the money has gone.

What a mule network is for

Every fraud that ends in a bank transfer leaves the criminal with the same problem: the money lands in an account that can be traced. Investment scams, invoice fraud, account takeover and romance fraud all produce funds that have to be moved, split and withdrawn before the victim reports the loss and the receiving institution can act. A mule network is the infrastructure that does this work.

The accounts in a network come from several places. Some belong to people recruited with offers of easy commission, often students or job seekers who are told they are processing payments for a business. Others are opened for the purpose, sometimes with stolen or synthetic identity documents, and used for a few days before being abandoned. In mobile-first markets the same approach extends to mobile-money wallets registered to SIM cards bought in bulk or in other people’s names.

What the people running a network value most is time. Each hour between the first credit and the final withdrawal is an hour in which a recall, a freeze or a fraud report could stop the cash-out.

The path from first credit to cash

Routes vary, but most networks follow a recognizable sequence, and each step is designed to look ordinary when it is viewed on its own. By the time the last step completes, the original payment has been divided across many accounts, at least two kinds of institution and possibly another country. Reconstructing the trail afterwards is possible. Recovering the money rarely is.

A typical sequence runs like this:

  • First-layer receipt: the victim’s payment lands in an account that is often only days or weeks old and has little prior history.
  • Fan-out: within minutes the balance is split into smaller transfers to a second layer of accounts, frequently at other institutions, so that no single recall can reach all of it.
  • Conversion to wallets: part of the value moves into mobile-money wallets, where transfers settle instantly and new accounts are quick to open.
  • Agent cash-out: wallet balances are withdrawn as cash through agents, often several agents in different areas, keeping each withdrawal small.
  • Corridor exit: what remains is sent across borders through remittance services in amounts sized to avoid attention, where recovery is slower and depends on cooperation between jurisdictions.

Why overnight batch review is too late

Many institutions still run transaction monitoring as a batch job that processes the previous day’s activity overnight. Alerts are reviewed the next morning, queued by priority and investigated over the following days. That cadence suited payments that took days to settle. It does not suit instant payments and mobile money, where the whole sequence above can finish in an afternoon.

Batch review also tends to look at accounts one at a time. A first-layer account that receives a single large credit and pays it straight out may raise an alert, but each second-layer account shows a modest inbound transfer followed by a cash withdrawal, which is normal behavior for many genuine customers. The pattern becomes obvious only when the accounts are viewed together, and batch rules are rarely built to do that.

The result is an alert that arrives with the account already empty. The investigator’s job shifts from stopping a loss to documenting one, and the report filed with the financial intelligence unit describes money that has already left the system.

Scoring before the money moves

Real-time scoring changes where the decision sits. Instead of reviewing yesterday’s transactions, the institution scores each payment as it is requested and returns a decision before it is booked: approve, hold for review, or block. A short hold on a high-risk outbound transfer removes the network’s main advantage, which is speed.

No single signal settles the question. Scored together, and against the account’s own history rather than one fixed threshold for every customer, a handful of signals separate a pass-through account from a busy but legitimate one far more clearly than any single rule.

The most useful signals for mule activity describe context rather than amount:

  • Account age and history, especially a large inbound credit to an account with little prior activity
  • Pass-through behavior, where funds leave almost as soon as they arrive and the balance returns to near zero
  • Fan-out to new payees, or to payees added in the same session as the transfer
  • Shared attributes, such as one device, phone number or address appearing across several unrelated customers
  • Movement from bank accounts into wallets, followed by cash withdrawals at several agents

Seeing the network instead of the account

Stopping one transfer helps the victim whose money it carries. Disrupting the network requires seeing that many apparently separate customers are connected. Entity resolution does this by matching records on shared identifiers, such as identity numbers, phone numbers, devices, email addresses and residential addresses, and linking them into a single view even when names are spelled differently.

Once the accounts are connected, a confirmed mule account raises the risk on everything linked to it. Investigators can freeze related accounts together rather than one at a time, alert the other institutions involved and file a single report that describes the network as a whole. The same view pays off again when the next scheme reuses some of the same accounts, devices or recruiters.

Dark Pools FinCrimes is built around this approach. Its real-time scoring API returns a risk score with an approve, review or block recommendation in milliseconds, evaluated against typologies that include mule rings, structuring, funnel accounts and agent cash-out laundering. Entity resolution collapses shared phones, devices and IDs into rings, and confirmed cases move into case management, with SAR filings generated directly from the case evidence.

Get started

Take the next step

Talk to the team behind this research about how the same thinking applies to your program.

All insights